Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Cette technique contourne le MFA car l’authentification s’effectue via l’infrastructure légitime de Microsoft.
T1027 — Obfuscated Files or Information (Defense Evasion)
Rather than linking to an obviously attacker-controlled site, the emails display what appears to be a legitimate SharePoint address while actually directing victims to a look-alike tenant hosted within the attacker's Microsoft 365 workspace.
Cette technique contourne le MFA car l’authentification s’effectue via l’infrastructure légitime de Microsoft.
Before any of that happens, the phishing kit runs a seven layer screening process designed to filter out security scanners and automated bots. It checks browser fingerprints, watches for natural mouse movement, and waits nearly a full second before activating.
ARToken operates as an affiliate of the EvilTokens phishing-as-a-service operation, which targets Microsoft 365 accounts and bypasses multi-factor authentication.
Once entered, the backend silently captures a working access token without asking for a password.
Before any of that happens, the phishing kit runs a seven layer screening process designed to filter out security scanners and automated bots. It checks browser fingerprints, watches for natural mouse movement, and waits nearly a full second before activating.
Automatisation des opérations de Business Email Compromise (BEC)
The researchers also found tools for conducting business email compromise attacks, including full Outlook mailbox access, the ability to send emails as compromised users, the ability to create inbox rules that automatically forward or hide messages, the ability to monitor multiple mailboxes for keywords simultaneously, and the ability to download email attachments.
Accès complet aux boîtes Outlook ... Surveillance simultanée de plusieurs boîtes compromises par mots-clés
They can also quietly set up inbox rules that hide or delete messages to cover their tracks.
The panel gives criminal operators a dashboard packed with more than eighty functions, covering everything from refreshing stolen tokens to reading a victim’s entire email inbox.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-as-a-Service platform used for Microsoft 365 device code phishing. It steals Microsoft 365 authentication tokens, can elevate access to Primary Refresh Tokens for persistence, access Outlook/SharePoint/OneDrive data, create inbox rules to hide messages, monitor compromised mailboxes, and support automated BEC operations.
PhaaS framework/panel targeting Microsoft 365 that enables device code phishing via OAuth 2.0 Device Authorization Grant abuse, acquisition and persistence of Primary Refresh Tokens, BEC operations, SharePoint/OneDrive exfiltration, and multi-mailbox monitoring. It also includes anti-analysis protections and exposes a large API surface for affiliates.
A phishing panel/kit that abuses Microsoft OAuth device code flow to steal Microsoft 365 session tokens, refresh stolen tokens, access email inboxes, browse/download SharePoint and OneDrive files, create inbox rules, and escalate access into longer-lived primary refresh tokens for persistence.
A recently deployed phishing-as-a-service platform targeting Microsoft 365 that uses device code phishing and token theft to bypass MFA, capture and refresh tokens, escalate to Primary Refresh Tokens, maintain persistent access, and enable Business Email Compromise, inbox monitoring, email rule manipulation, and SharePoint/OneDrive data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.